Trust
How Hygieia handles patient information
You're trusting Hygieia inside the exam room, so here is exactly what happens to what you record, type, and store — in plain language, including the parts most products leave out.
The short version
- Notes are stored tokenized: patient identities live in a separate, access-controlled vault and are joined back only on your screen.
- Our AI language model never sees a patient identity — it works entirely on placeholder tokens like
[PT_NAME]and[DATE_1]. - Encounter audio goes to one place only: a HIPAA business-associate medical transcription service, transiently, to produce your transcript.
- Everything is encrypted in transit and at rest. We sign a Business Associate Agreement with your practice, and every vendor that touches protected health information has signed one with us.
Where your data lives
Notes, transcripts, and your preferences are stored in Google Cloud (United States) under a Business Associate Agreement, encrypted at rest and in transit. Patient identities are not stored inside notes — they live in a separate identity vault, and every read and write of that vault is gated and audited. On your phone, the clinical database is fully encrypted, its keys are protected by your device's biometric hardware, and the app locks itself when you step away.
What AI services can and cannot see
| Service | What it receives | Agreement |
|---|---|---|
| Anthropic — drafts your note | Tokenized text only: placeholders, never names, dates of birth, or record numbers | Business Associate Agreement |
| Deepgram — medical transcription | Encounter audio, transiently, to return your transcript; nothing is retained on their side | Business Associate Agreement |
| Google Cloud — storage & compute | The encrypted data described above | Business Associate Agreement |
An honest note about audio: a recording naturally contains whatever was said aloud — names included. That is why transcription happens only under a business-associate agreement, why audio is never sent to the language model, and why de-identification runs on the transcript before any text moves on to AI drafting.
What never carries patient information
Emails from Hygieia never contain patient information. Push notifications are content-free — the app fetches what it needs over an authenticated connection. Application logs record identifiers and counts, never clinical content.
Retention and deletion
Encounter audio is kept only until it has done its job: once a transcript and note exist, it is deleted automatically after a short retention window, and you can delete it sooner yourself. Audio that has not yet been transcribed is deliberately kept longer — it may be your only record of the visit. Deleting your account deletes your data; the limited billing and audit ledgers we are required to keep contain no clinical content.
Inside your practice
Access is per-physician by default. Staff you invite see only notes you have signed off, under role-based access, and their identity reads are audited. Signing in to the web dashboard requires two-step verification; the mobile app is protected by your device biometric.
If something ever goes wrong
We maintain a written security risk analysis reviewed annually, daily backups with point-in-time recovery, and a breach-response playbook. If an incident affects your patients' information, we will notify your practice without unreasonable delay, within the timelines committed in our Business Associate Agreement — with facts, not spin.
A few honest limits
No system is breach-proof, and we won't pretend otherwise. Our commitments are structural: minimize what any party — including our own AI services — can ever see, encrypt everything, audit access to identities, and tell you the truth quickly if something goes wrong.
One practical tip
On shared or hospital workstations, sign out when you step away.
Questions about any of this? Visit our support page. See our Privacy Policy and Terms of Service for more.